CVE-CVE-2026-80428
Severity
CRITICAL
CVSS Score
9.8
Description
ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components/ILIAS/AuthShibboleth/resources/shib_logout.php runs in a context that ilInitialisation exempts from authentication, and its logout-notification handler locates the session to terminate by reading every live row of the session table and passing each row's stored data to a hand-written parser that calls unserialize without restricting which classes may be constructed. Any serial...
PoCs for CVE-CVE-2026-80428
CVE-2026-80428
General
Python
0
Zipkoppie
2026-09-03